CVE-2021-42859

A memory leak issue was discovered in Mini-XML v3.2 that could cause a denial of service. NOTE: testing reports are inconsistent, with some testers seeing the issue in both the 3.2 release and in the October 2021 development code, but others not seeing the issue in the 3.2 release
References
Link Resource
https://github.com/michaelrsweet/mxml/issues/286 Exploit Issue Tracking Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:mini-xml_project:mini-xml:3.2:*:*:*:*:*:*:*

History

07 Nov 2023, 03:39

Type Values Removed Values Added
Summary ** DISPUTED ** A memory leak issue was discovered in Mini-XML v3.2 that could cause a denial of service. NOTE: testing reports are inconsistent, with some testers seeing the issue in both the 3.2 release and in the October 2021 development code, but others not seeing the issue in the 3.2 release. A memory leak issue was discovered in Mini-XML v3.2 that could cause a denial of service. NOTE: testing reports are inconsistent, with some testers seeing the issue in both the 3.2 release and in the October 2021 development code, but others not seeing the issue in the 3.2 release

07 Jun 2022, 15:55

Type Values Removed Values Added
CWE CWE-772
CVSS v2 : unknown
v3 : unknown
v2 : 5.0
v3 : 7.5
First Time Mini-xml Project
Mini-xml Project mini-xml
References (MISC) https://github.com/michaelrsweet/mxml/issues/286 - (MISC) https://github.com/michaelrsweet/mxml/issues/286 - Exploit, Issue Tracking, Third Party Advisory
CPE cpe:2.3:a:mini-xml_project:mini-xml:3.2:*:*:*:*:*:*:*

02 Jun 2022, 14:15

Type Values Removed Values Added
Summary A memory leak issue was discovered in Mini-XML v3.2 that could cause a denial of service. ** DISPUTED ** A memory leak issue was discovered in Mini-XML v3.2 that could cause a denial of service. NOTE: testing reports are inconsistent, with some testers seeing the issue in both the 3.2 release and in the October 2021 development code, but others not seeing the issue in the 3.2 release.

26 May 2022, 12:57

Type Values Removed Values Added
New CVE

Information

Published : 2022-05-26 12:15

Updated : 2024-04-11 01:13


NVD link : CVE-2021-42859

Mitre link : CVE-2021-42859

CVE.ORG link : CVE-2021-42859


JSON object : View

Products Affected

mini-xml_project

  • mini-xml
CWE
CWE-772

Missing Release of Resource after Effective Lifetime